Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-46623: CVE-2022-46623/CVE-2022-46623 at main · sudoninja-noob/CVE-2022-46623

Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVE
#sql#vulnerability#php

> [Suggested description]

> Judging Management System v1.0.0 was discovered to contain a SQL

> injection vulnerability via the username parameter.

>

> ------------------------------------------

>

> [Vulnerability Type]

> SQL Injection

>

> ------------------------------------------

>

> [Vendor of Product]

> https://www.sourcecodester.com

>

> ------------------------------------------

>

> [Affected Product Code Base]

> Judging Management System - V 1.0.0

>

> ------------------------------------------

>

> [Attack Type]

> Local

>

> ------------------------------------------

>

> [Impact Code execution]

> true

>

> ------------------------------------------

>

> [Impact Escalation of Privileges]

> true

>

> ------------------------------------------

>

> [Attack Vectors]

> Go to Login Panel and try to bypass

>

> In request payload, set

>

> username : ‘or’’=’

>

> password : Judging

>

> ------------------------------------------

>

> [Reference]

> https://www.sourcecodester.com/php/15910/judging-management-system-using-php-and-mysql-free-source-code.html

>

> ------------------------------------------

>

> [Discoverer]

> Sanjay Singh

Use CVE-2022-46623

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907